social.coop is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Fediverse instance for people interested in cooperative and collective projects. If you are interested in joining our community, please apply at https://join.social.coop/registration-form.html.

Administered by:

Server stats:

489
active users

#dns

52 posts47 participants12 posts today

Online gambling operators are sponsoring charities?? If only :(

We've identified a malicious gambling affiliate whose specialty is to buy expired domain names which used to belong to charities or reputable organisations.

Once they own a domain, they host a website impersonating its previous owner, where they claim to "deeply appreciate the support from [their] sponsors", which surprise surprise, all turn out to be dubious online gambling companies.

Because the domain they are taking over is often abandoned or managed by non-technical people, its previous owner often doesn't notify anyone that they've lost control of their website, so it continues being referenced in genuine content, and it continues getting traffic from old links scattered throughout the internet.

teampiersma[.]org (screenshots below)
americankayak[.]org
getelevateapp[.]com
hotshotsarena[.]com
nehilp[.]org
questionner-le-numerique[.]org
sip-events[.]co[.]uk
studentlendinganalytics[.]com
thegallatincountynews[.]com

Comparison content:
2018: web.archive.org/web/2018011904
2025: web.archive.org/web/2025040109

“The UK’s proposed measures for court orders to suspend IP addresses and domain names” | …the UK wants to globally censor or take down IP addresses & DNS domains

Excellent little blog post from Neil:

https://decoded.legal/blog/2025/04/the-uks-proposed-measures-for-court-orders-to-suspend-ip-addresses-and-domain-names/

A stylised d, ., and l, in white, on a black background. They look a bit like a circuit board
decoded.legalThe UK's proposed measures for court orders to suspend IP addresses and domain names
More from Neil Brown

De Internet Corporation for Assigned Names and Numbers (ICANN) voerde op 5 april 2024 nieuwe abusebestrijdingsregels in voor registry’s en registrars. Deze regels verplichten registrars en registry-operators om proactief op te treden tegen veelvoorkomende vormen van #DNS-misbruik. 12 maanden later lijkt het erop dat deze regels effectief zijn: de aanpak van DNS-abusemeldingen is zichtbaar effectiever geworden. Bewijs dat de maatregelen werken?sidn.nl/nieuws-en-blogs/abuseb

Banner-laptop-with-ICANN-logo
SIDN - Het bedrijf achter .nlAbusebestrijdingsregels ICANN lijken effectief | Cybersecurity | SIDNEen jaar geleden voerde ICANN nieuwe abusebestrijdingsregels in voor registry’s en registrars. 12 maanden later lijkt het erop dat deze regels effectief zijn: de aanpak van DNS-abusemeldingen is zichtbaar effectiever geworden.

I wrote something for myself, and figured it might be useful for others: a small service that automatically discovers LXCs and VMs in a Proxmox cluster and acts as a DNS server pointing to the IP(s) for them. It's called, somewhat unimaginatively... proxmox-service-discovery:
github.com/andrew-d/proxmox-se

As a short example: if you have a Proxmox cluster running lxc1, lxc2, and vm3, and you run proxmox-service-discovery with the "--dns-zone=example.com" option, then it will run a DNS server that answers queries for lxc1.example.com with all the IP addresses for lxc1, and so on for lxc2 and vm3.

It's pretty basic but well-tested, and seems to work well for my use-case. Feedback appreciated, along with bug reports, PRs, and so on!

A DNS server that automatically discovers VMs and containers (LXCs) in your Proxmox cluster and makes them available via DNS - andrew-d/proxmox-service-discovery
GitHubGitHub - andrew-d/proxmox-service-discovery: A DNS server that automatically discovers VMs and containers (LXCs) in your Proxmox cluster and makes them available via DNSA DNS server that automatically discovers VMs and containers (LXCs) in your Proxmox cluster and makes them available via DNS - andrew-d/proxmox-service-discovery

Is the sky fluxxing?! Last week a CISA advisory on DNS Fast Flux created a lot of buzz. We have an insider's take.

Fast Flux is a nearly 20 year old technique and is essentially the malicious use of dynamic DNS. It is critical that protective DNS services understand this -- and all other DNS techniques -- on that we agree.

What we also know as experts in DNS is that there are many ways to skin a cat, as they say.

#dns #threatintel #cisa #malware #phishing #threatintelligence #infobloxthreatintel #infoblox #cybercrime #cybersecurity #infosec

blogs.infoblox.com/threat-inte

Infoblox Blog · Disrupting Fast Flux and more advanced tacticsA recent Cybersecurity Advisory (1) from the Cybersecurity and Infrastructure Security Agency (CISA) notified organizations, Internet service providers (ISPs), and cybersecurity service providers about the threat posed by fast flux enabled malicious activities.